216.73.217.22

Inside the Dragon: DragonForce Ransomware Group

· Published 27/09/2024 13:43 · Modified 27/09/2024 14:11

Export JSON

Essential information

Published
27/09/2024 13:43
Modified
27/09/2024 14:11
Tags
2024-09-27 dragonforce lockbit3.0
Related entities
5 observables, 1 intrusion sets (apt), 5 techniques (mitre), 2 malware, 3 others

Description

In this blog, Group-IB delves into the inner workings of the ransomware group. Discovered in August 2023, has been targeting companies in critical sectors using a variant of a leaked builder, and more recently in July 2024 with their own variant of ransomware. operates a Ransomware-as-a-Service (RaaS) affiliate program utilizing a variant of , and the other, though initially claimed as original, is based on ContiV3. The group employs double extortion tactics, encrypting data, and threatening leaks unless a ransom is paid.

External references